ZeroHour
Infosecurity Magazinepublished ()ingested Kevin Poireault

Colt Customers Face Prolonged Outages After Major Cyber Incident

highRansomwareimportance 60CVE-2025-53770

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2025-53770
Unauthenticated Deserialization RCE in Microsoft SharePoint Server on-premises

CVE-2025-53770 is a deserialization of untrusted data vulnerability (CWE-502) in Microsoft SharePoint Server on-premises that allows an unauthorized attacker to execute code over a network. It is triggered when the server deserializes attacker-controlled data, can be chained with CVE-2025-53771, and it bypasses the fixes issued for CVE-2025-49704, meaning the earlier patches are insufficient. Successful exploitation yields remote code execution on the SharePoint server, and ransomware operators are known to be using it. Any organization running SharePoint Server on-premises is affected, particularly internet-facing deployments and end-of-life versions such as SharePoint Server 2013 and earlier that can no longer be patched. The flaw is being actively exploited — it was added to CISA's KEV on 2025-07-20 with known ransomware use — and EPSS assigns it a 100% probability of exploitation within 30 days.

Do: Apply Microsoft's updated SharePoint Server security updates that fix CVE-2025-53770 — these include more robust protection than the earlier CVE-2025-49704 updates — and ensure the companion CVE-2025-53771 is also addressed, following CISA and vendor mitigation instructions for supported versions. Disconnect public-facing SharePoint Server 2013 or earlier (EOL/EOS) instances, minimize internet exposure of supported servers, and hunt for signs of compromise given the known ransomware exploitation.

9.8100% KEV ransomware PoC ×3
  • Microsoft SharePoint Server (on-premises) Specific version ranges not enumerated in the source data; Microsoft SharePoint on-premises is affected. CISA notes SharePoint Server 2013 and earlier are EOL/E
mass≈25,000–100,000 internet-exposed on-premises SharePoint servers (public internet-wide scans); total on-prem installed base plausibly >1M users
Full article368 words · extracted from infosecurity-magazine.com · click to collapse

Colt Technology Services is experiencing a “cyber incident” that has forced the company to shut down some services temporarily.

On August 14, the London-based telecommunications giant publicly confirmed that an internal system was breached.

Although this system was disconnected from its customer-facing infrastructure, the company has taken some systems offline in response to the incident.

This action has resulted in the disruption of some of the support services, including hosting and porting services, Colt Online and Voice API platforms. Both are still unavailable for customers at the time of writing.

Customers have been advised to contact the company via email or phone if they need to get in touch.

Warlock Ransomware Gang Claims Attack

Ransomware monitoring platforms Ransomware.live and RansomLook detected that the Warlock ransomware group claimed responsibility for the breach on August 16.

At the time of the incident, a user of the RAMP hacker forum, who claimed to be claimed to be affiliated with Warlock, posted that they were selling “one million stolen documents” from Colt for $200,000.

The data included what they describe as financial records, employee and customer data, executive communications, internal emails and proprietary software development files.

To substantiate the claim, the threat actor has released a 400,000-file sample of data as proof of the breach’s legitimacy. According to security researcher Kevin Beaumont, it appears that the filenames included in the sample are from real Colt-related files.

Exploited SharePoint Flaw May Have Led to Breach

The breach may have originated from activity which targeted the company’s SharePoint servers in order to exploit CVE-2025-53770, one of the two vulnerabilities involved in the ‘ToolShell’ exploit chain, Beaumont has suggested in his analysis shared on social media.

Beaumont’s analysis of Shodan scan data found that IP addresses linked to cybercriminal operations were observed probing Colt’s systems before the attack.

He further noted that Colt’s SharePoint servers were abruptly taken offline, with evidence pointing to possible webshell implants, a common tactic for maintaining unauthorized access.

Public records also indicated that Colt rushed to implement firewall protections for its EU infrastructure on the same day it first disclosed technical disruptions, he added.

Photo credit: aileenchik / Shutterstock.com

Listen now: ToolShell Deep Dive –The SharePoint Exploit Crisis Uncovered

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.infosecurity-magazine.com/news/colt-outages-after-major-cyber/